Impact
A buffer overflow occurs in Apache HTTP Server's mod_vhost_alias module when a client sends a Host header longer than 8192 bytes while VirtualDocumentRoot uses a hostname format specifier. The flaw can lead to a denial of service or, under certain conditions, arbitrary code execution. The weakness is a classic stack-based buffer overflow (CWE-121).
Affected Systems
Apache Software Foundation's Apache HTTP Server, versions through 2.4.68, on all platforms. The vulnerability is present in any configuration that uses VirtualDocumentRoot with hostname format specifiers and has LimitRequestFieldSize increased beyond the default value.
Risk and Exploitability
The vulnerability is accessible to a remote client via an HTTP request and requires only an oversized Host header. The CVSS score of 7.5 indicates a medium to high severity. While the EPSS score is not available and the issue is not listed in CISA's KEV catalog, the potential impact of arbitrary code execution or service disruption makes it a high‑risk flaw. Exploitation would involve sending a specially crafted HTTP request with a large Host header to trigger the overflow. The condition that virtual hosting and a non-default LimitRequestFieldSize are enabled is a prerequisite for exploitation.
OpenCVE Enrichment